It's easy enough to include links back to the website to view the attachments, and that's on the todo list.
Is it feasible to make those links work, regardless of whether the user is signed in? That's valuable for email-only members.
The only "trick" to this I'm aware of is to include a randomly generated value in the URL so that having one such link in hand doesn't allow one to discover others.